PT-2018-6142 · Timespan · Timespan

Cristianstaicu

·

Published

2018-06-07

·

Updated

2020-02-20

·

CVE-2017-16115

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: timespan (affected versions not specified)
Description: The timespan module is vulnerable to a regular expression denial of service. This issue can cause significant amplification, with 50,000 characters of untrusted user input resulting in the event loop being blocked for around 10 seconds.
Recommendations: For all affected versions, consider using a functionally equivalent alternative package as a replacement for timespan. As a temporary workaround, ensure that user input is not being passed into timespan, or drastically reduce the maximum length of such user input, limiting it to 150 characters or less.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-16115
GHSA-F523-2F5J-GFCG

Affected Products

Timespan